Update vulnerable brace-expansion dependencies - #136
Raymond Zhao (rzhao271) with Copilot wants to merge 5 commits into
Conversation
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
|
Copilot Please first revert all dependency and lockfile changes made in this PR so the branch is restored to its original dependency state. Then regenerate the update from that clean baseline while observing the repository’s 7-day npm release hold: npm update brace-expansion --package-lock-only --min-release-age=7
npm install --min-release-age=7
npm testThere are two distinct Component Governance dependency paths, and both must remain on their respective major lines:
|
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
Addressed in d5e5921. I restored the lockfile to the pre-PR baseline first, then regenerated with |
Component Governance reported vulnerable
brace-expansionversions in distinct npm dependency paths.Dependency lockfile updates
brace-expansiontransitive entries inpackage-lock.json.Additional vulnerable path
2.xbrace-expansionpath as well, since the current advisory also flags that installed range.